All roles

NIS2 Security Governance Consultant

Help energy companies, municipal utilities and public bodies meet NIS2 obligations under German implementation law. You build ISMS structures, risk processes and incident reporting that work in practice.

Apply nowTakes about 3 minutes

About the role

The German NIS2 implementation act brings thousands of new organisations into scope, including many municipal utilities and public service providers. Most of them need a working information security management system rather than another policy binder. This role, based in our Berlin office, builds those systems with clients. You scope the ISMS, set up risk management and incident reporting to the BSI, and prepare management for its personal accountability. You work with our OT security and cloud teams.

What you will do

  • Run NIS2 applicability and gap assessments and present results to management boards
  • Build or extend an ISMS to ISO 27001 or BSI IT-Grundschutz, scoped to the client's critical services
  • Set up incident handling and the reporting chain to the BSI within the statutory deadlines
  • Design supply-chain security requirements for contracts and supplier audits
  • Prepare clients for audits and evidence requests

What you bring

  • 5+ years in information security governance, audit or risk management
  • Practical experience implementing ISO 27001 or BSI IT-Grundschutz
  • Good understanding of NIS2 and its German implementation
  • Ability to write clear policies and explain them to non-specialists
  • German at B2 or above

Good to have

  • ISO 27001 Lead Auditor or Lead Implementer certification
  • Experience with KRITIS audits under §8a BSIG
  • Knowledge of DORA or the Cyber Resilience Act

Languages

English (C1), German (B2)

Skills

  • NIS2
  • ISO 27001
  • BSI IT-Grundschutz
  • ISMS
  • Risk management
  • Incident reporting
  • Supplier security